Sam Na writes practical digital-workflow guides for freelancers who want clearer business systems without adding unnecessary tools or daily admin.
The easiest password system is not the one with the most folders. It is the one that makes the right identity obvious before you sign in.
If you want to separate personal and business passwords without creating a second job for yourself, the goal is not to build two complicated security systems. The goal is to create one clear boundary that your password manager, browser, and daily habits can follow automatically.
Freelancers often begin with a single digital identity. The same browser holds personal shopping accounts, a private email address, cloud storage, social media, a portfolio login, invoicing software, project platforms, and client portals. That feels efficient when the business is small. The trouble appears later, when it becomes hard to tell which credentials belong to you personally, which belong to your freelance business, and which exist only because a client gave you temporary access.
Separation solves an ownership problem as much as a security problem. A business account may need to survive a laptop replacement, a new phone, a change in your personal email address, a future assistant, or a move from one password manager to another. If all of those credentials are mixed into one personal vault with no naming rules or context, every change becomes a sorting project.
The solution does not have to be dramatic. You do not necessarily need two computers, two phones, or two completely unrelated password-manager subscriptions. For many solo professionals, a practical setup can be built from three simple layers: a clear definition of what counts as business, a dedicated business vault or equivalent storage boundary, and a browser or device context that makes business autofill easy to recognize.
Ownership, storage, and sign-in context. Decide who owns the account, keep the credential in the matching vault, and make your browser or device show you which side you are using before autofill happens.
Current NIST guidance supports the use of password managers and notes that distinct passwords matter because reusing a compromised password can expose other accounts. The UK National Cyber Security Centre also advises organisations to keep work and personal password storage clearly separated, especially when products offer both personal and work vaults. Those principles translate well to freelance work: make the separation visible, easy to use, and difficult to cross by accident.
This guide focuses on that boundary. It does not try to turn a solo freelancer into an IT department. Instead, it shows how to organize business passwords so the system stays usable on a normal workday, including when you work from a laptop, switch devices, travel, or manage accounts for several projects at once.
Define what belongs on the business side
Start with account ownership, not the website name
The same service can be personal in one context and business in another. A Google account might hold family photos, or it might control your business email and client documents. A social platform might be where you follow friends, or it might be the account that publishes your professional work. That is why the first rule should be based on ownership rather than on the brand of the service.
Ask a simple question: If I stopped freelancing tomorrow, would I still want this account as part of my private life? If the answer is yes, it is probably personal. If the account exists because you invoice clients, deliver work, operate a professional website, manage business expenses, market your services, or communicate under your business identity, it belongs on the business side.
This distinction becomes especially useful for freelancers who do not have a registered company or separate legal entity. You do not need a corporation to create an operational boundary. The boundary is about how you control and recover the account. A business credential should not depend unnecessarily on a personal inbox, a personal browser profile, or a private password collection that no one could understand later.
Separate credentials that protect your business identity first
Do not try to classify every account in one afternoon. Start with the credentials that would cause the most disruption if they became inaccessible or mixed with your personal identity. That normally includes business email, your website and domain account, invoicing or accounting software, cloud storage used for client files, professional social accounts, project-management tools, payment platforms, scheduling services, and the administrative logins that control those services.
The exact list will differ by profession. A freelance designer may care most about cloud storage, design software, portfolio hosting, and client review platforms. A consultant may prioritize email, calendar, video meetings, proposals, and document-signing services. A developer may have code repositories, cloud infrastructure, deployment tools, and developer accounts. The important part is not the number of tools. It is whether the credential belongs to the business workflow.
Once those accounts are clearly classified, everyday decisions get easier. When a browser asks where to save a password, you know which vault should receive it. When you replace a device, you know which business credentials need to return. When you audit old accounts, you can review business access without scrolling through streaming subscriptions, shopping accounts, and personal apps.
Treat client-owned access as a third category, even if it lives inside the business system
A useful mental model has three ownership labels: personal, business-owned, and client-owned. You may still store business-owned and client-owned items inside the same approved business password system, but the labels should remain distinct. A credential for your own invoicing platform is not the same kind of asset as a login a client issued for a temporary project.
This matters because the end of access is different. Your business-owned credentials should remain with you. Client-owned credentials may need to be removed when the engagement ends, rotated by the client, or handled under the client's own security policy. Keeping that distinction visible prevents the business vault from becoming a permanent archive of old client access that nobody intended you to keep.
Stays with your private life.
Private email, personal shopping, family services, personal subscriptions, and accounts you would keep even if your freelance work ended.
Exists to run your freelance operation.
Business email, domain, portfolio, invoicing, work storage, professional tools, and other accounts you control for the business.
Exists because a client granted access.
Keep it clearly labeled so you can review, return, or remove access when the engagement changes.
Decide by recovery and ownership.
If an account mixes personal and business use, decide which identity should control it long term and separate future use from there.
Separate accounts by who should own and recover them, not by the logo on the login page. Personal, business-owned, and client-owned are more useful categories than trying to memorize dozens of exceptions.
Choose the simplest vault architecture
One password manager can still provide a real boundary
Many freelancers assume that separation requires two entirely different password-manager products. It can, but it does not always have to. Some password managers support separate vaults, collections, spaces, profiles, or business and personal areas under one application. If the separation is clear and the product prevents accidental cross-access, one application can reduce friction while still keeping business credentials organized.
The important question is not whether there is one app icon or two. The important question is whether you can reliably tell where a new credential is being saved and where an existing credential is being filled. If you constantly have to inspect tiny labels before every save, the architecture is too fragile for daily use. If the work area is visually distinct and predictable, the system can remain simple.
The NCSC's password-manager guidance for organisations makes a similar point: when a product offers personal and work vaults, there should be strong separation and it should be difficult to save a password to the wrong place by accident. A freelancer can apply the same usability test. Security that depends on perfect attention every time is harder to sustain than security that makes the correct choice the default.
Use a separate business account when ownership needs to be independent
A separate business password-manager account becomes more attractive when your business identity needs to survive changes in your personal identity. For example, you may want the business vault to use a dedicated business email address, separate billing, its own recovery process, and a clear path for adding another authorized person later.
That does not mean you should create extra accounts just to feel more secure. Every additional account has its own setup, recovery, billing, and device enrollment. The extra boundary should solve a real problem. If you already have a password manager that provides a clearly separated business vault and you are comfortable with how ownership works, a second subscription may add more complexity than value.
On the other hand, if your current personal password manager cannot distinguish work from personal items, always opens into one giant list, or syncs business credentials into places where you do not want them, a separate business account can create a cleaner operational line. The right architecture is the one that reduces accidental mixing while remaining easy enough to use every day.
Choose boundaries based on your device reality
A freelancer who works only from one privately owned laptop has different needs from a digital nomad who uses a laptop, tablet, and phone across several countries. Before choosing a vault layout, list the devices on which you actually need business credentials. Then decide which devices should have access to the business vault and which should remain personal-only.
Avoid turning convenience into automatic access everywhere. If you never work from a tablet, there may be no reason to sync the full business vault to it. If your phone is essential for business travel, then phone access may be necessary, but it should be protected with the device security and account protections appropriate to the password manager you use.
This is also a good time to notice legacy devices. An old laptop in a drawer, a previous phone, or a tablet you lent to a family member can remain signed in longer than you remember. A clean business password system includes knowing which devices are authorized to access it, not merely which folders exist inside the vault.
One manager, clearly separated vaults.
Good when the product makes work and personal storage visually distinct and hard to mix by accident.
Separate business account.
Useful when you want dedicated business email, billing, recovery, device access, or future team ownership.
Multiple tools with no clear reason.
Extra apps can create forgotten credentials, inconsistent saving, and confusion about which manager should handle a login.
Can you identify the correct vault in one glance?
If not, simplify or change the visual boundary before migrating everything.
A business password vault for a freelancer should create a clear ownership boundary without forcing unnecessary daily decisions. Separate vaults can be enough; a separate account is useful when business ownership, recovery, or future access needs to stand on its own.
Build a low-friction daily workflow
Make the work context visible before you reach the login page
Most password mistakes happen because the context is unclear. You open a familiar website, the browser offers an account, and you choose the first one that appears. Later you discover that a personal email was used for a business subscription, a client tool was saved into the personal vault, or a business credential is now syncing through the wrong browser profile.
A simple fix is to make the context visible earlier. Use a dedicated browser profile for freelance work on desktop when your browser supports it. Give it a clearly different name and appearance from your personal profile. Sign the work profile into the business accounts you actually need, and avoid adding personal accounts unless there is a specific reason.
Google's Chrome documentation, for example, states that profiles can keep information such as bookmarks, history, passwords, and settings separate, and specifically identifies work-versus-personal separation as a use case. Other browsers and operating systems may offer different profile models, so use the equivalent separation supported by your own tools.
Pair the browser profile with the matching vault
The browser profile is not the password vault, and it should not be treated as one unless you intentionally use the browser's password-management feature. Think of the profile as the workspace that tells you which identity you are using. Then configure your chosen password manager so the work profile naturally points you toward the business vault.
If your password manager lets you choose which vaults appear in a browser extension, hide personal vaults from the work context when practical. If it does not, use labels or naming rules that make the business destination unmistakable. The fewer irrelevant credentials the manager shows during a work login, the less attention you need to spend on avoiding the wrong one.
The same principle applies on mobile, but the implementation may be different. Mobile operating systems often handle browsers, apps, and autofill more centrally than desktop browsers do. Do not assume that creating a desktop browser profile automatically creates the same separation on your phone. Check how your device handles password autofill and decide whether business credentials need to be available there at all.
Use naming rules that answer questions at a glance
Good names reduce decisions. Instead of naming vaults with vague labels such as “Main,” “Other,” or “Private 2,” use names that describe ownership: “Personal,” “Freelance Business,” and, if needed, a clearly marked client-specific area. The labels should still make sense six months from now when you have forgotten why you created them.
Inside the business vault, folders and tags are optional. Use them only when they help you retrieve or review accounts. A freelancer with thirty business credentials may not need a folder for every project. A few broad groups such as “Core Business,” “Marketing,” “Finance Tools,” “Production,” and “Client Access” may be easier to maintain than a perfect taxonomy.
Avoid using the password manager as a project-management system. The vault should answer security and ownership questions, not mirror every client folder on your computer. If an item needs a note, keep the note short and operational: who owns the account, which business email is attached, and whether access should be reviewed when a project ends.
Create a default rule for new accounts
A system becomes easy when new decisions are predictable. Before creating any new account, decide whether it is personal or business. If it is business, open the work browser context first, use the business identity that should own the account, and save the credential directly into the business vault. Do not create it personally and promise yourself that you will move it later.
This single habit prevents future cleanup. It also makes subscriptions easier to understand because billing receipts, renewal notices, password-reset emails, and security alerts are more likely to arrive in the business communication channel rather than disappearing into a crowded personal inbox.
Open your business browser profile or workspace before visiting the sign-up page.
Register the account with the business identity that should control recovery and future administration.
Do not create a temporary personal copy unless there is a defined reason.
Record ownership or review notes when they will help later; avoid turning the vault into a second project tracker.
The best separation happens before the password is saved. Open the business context first, use the business identity, and let the matching vault become the default destination.
Sort accounts by ownership and recovery
Your business email should not be just another login
Business email often sits at the center of account recovery. Subscription notices, password resets, security warnings, and invitations may all arrive there. That makes the business inbox part of your credential system even though it is not technically a password manager.
When you organize business passwords, look at which email address each service uses. If a core business tool is attached to a personal address only because that address was convenient when you first signed up, consider whether the account should be moved to the business identity. Follow the service's official account-change process and verify that the new address works before removing the old one.
Do not change every address simply to make a spreadsheet look tidy. The goal is continuity. Prioritize accounts where personal ownership would create a real problem if your business grew, if you changed personal email providers, or if another authorized person later needed to understand the business setup.
Separate the password from the recovery path
Moving a credential into a business vault does not automatically move the account itself. The login may still be recoverable through a personal email address, a personal phone number, or another personal account. That is why a password inventory should include recovery ownership, not just storage location.
For core business accounts, ask whether the recovery route is appropriate for the business. You may still choose to use a personal phone as part of a recovery process, especially as a solo freelancer, but that should be a deliberate decision rather than an accident left over from setup. Where a service offers business-appropriate recovery options, document enough context to know what controls the account.
This is also where freelancers based in South Korea but serving overseas clients can avoid unnecessary confusion. A business may use an international SaaS platform, a Korean mobile number, a global email provider, and client systems in several countries at the same time. The country mix is less important than knowing which identity and device are expected during recovery. Keep those relationships clear before a travel day or device replacement forces you to discover them under pressure.
Do not turn the vault into a copy of every sensitive item you own
A password manager can store more than passwords, but convenience should not automatically become accumulation. If the business vault contains account credentials, payment details, private notes, identity documents, client secrets, software keys, and every recovery record in one undifferentiated place, the system becomes harder to review and the consequences of exposure become broader.
Store what you need for the workflow and what the product is appropriate for. Use dedicated systems when a different type of record belongs elsewhere. For example, a client contract belongs in your document system, not in a password note simply because the vault is encrypted. A project brief belongs in project storage. Keeping the vault focused makes business password management easier to audit and easier to migrate.
Personal you, your freelance business, or the client?
Make sure the recovery address matches the long-term owner where practical.
Remove obsolete or unnecessary access rather than syncing everywhere by default.
Business-owned access stays with the business; client-owned access may need review or removal.
A credential is not fully separated just because it sits in the right vault. Check the account owner, recovery email, recovery device, and end-of-access plan so the business boundary exists outside the password manager too.
Prevent autofill from crossing contexts
Autofill should reduce effort without hiding identity
Password-manager autofill is valuable because it removes the need to memorize or manually type credentials. NIST's current authentication guidance explicitly says verifiers should allow password managers and autofill. But convenience can become confusing when the manager offers several identities for the same website and does not make ownership obvious.
For freelancers, the risk is often not that autofill itself is unsafe. The practical problem is choosing the wrong identity. You may have a personal and business account on the same cloud service, two separate social accounts, or several client workspaces hosted under the same domain. A clean business setup should make those choices understandable before you submit the login form.
Use clear item names inside the password manager. If the manager supports custom titles, write titles that identify the owner or purpose rather than repeating the website name. “Business — Portfolio Admin” is more useful than three entries all named after the same service. Do not put secret values into the title; the title should only help you distinguish context.
Reduce the number of credentials shown in the wrong workspace
If your password manager or browser lets you limit which vaults are available in a profile, use that feature to reduce noise. A work browser does not need to suggest your personal streaming or shopping credentials. Likewise, your personal browsing context does not need to surface every business admin login.
This is less about building a perfect technical wall and more about making mistakes less likely. Every irrelevant suggestion adds a tiny decision. When those decisions happen dozens of times a week, people eventually click the wrong option. A quiet autofill menu is a usability advantage.
Be especially careful with shared or borrowed devices. A browser profile is not a substitute for a separate operating-system user account or proper device access control. Google notes that someone with access to a computer can switch Chrome profiles, so profiles should be treated as an organizational boundary, not as the only security control on an untrusted shared device.
Know when not to save a credential locally
Not every login you touch should be saved permanently. A one-time client account, a temporary test environment, or a short-lived invitation may not need to remain in your long-term vault after the work ends. Before saving, ask whether you will need the credential again and whether the client expects you to retain it.
If a client provides a managed access method or asks you to use a particular password manager, follow that arrangement rather than copying the password into your own personal system for convenience. Client access can involve contractual or organizational rules that are separate from your normal freelance setup.
The goal is not to avoid saving passwords. The goal is to save the right credentials in the right place for the right length of time. That creates a business password system that is easier to trust because old access does not accumulate forever.
Several logins appear for one domain.
Rename entries by owner or purpose so you can distinguish personal, business, and client contexts before filling.
Every vault appears everywhere.
Limit visible vaults or use separate work browsing contexts when your tools support that separation.
A browser profile is not a device-security boundary.
Use trusted devices and appropriate device accounts, locks, and access controls.
Do not keep every client credential forever.
Review temporary access when the project, contract, or authorization ends.
Autofill should make the correct business identity easier to use, not hide which account you are choosing. Reduce irrelevant suggestions, label similar logins clearly, and treat temporary access as temporary.
Migrate existing passwords without chaos
Do not begin by moving everything
A mixed password vault can look intimidating because it may contain years of saved credentials. The fastest way to create more work is to make “perfectly classify every password” the first step. Instead, move the accounts that matter to your current business operations and let old, low-priority items wait.
Start with the services you use weekly. Move your business email, domain and website administration, active work platforms, invoicing or payment tools, current cloud storage, professional social accounts, and any other service you would immediately notice if it stopped working. That gives you a functioning business vault quickly.
Then migrate less frequent accounts in batches. Each time you log into an old business service, move or re-save it into the correct business location and remove the duplicate from the personal side after you confirm the business copy works. This “move when touched” approach can clean up a large vault over time without requiring a weekend migration project.
Use export and import only when you understand the exposure
Password managers often provide export and import functions, but exports can create files that deserve careful handling. Depending on the product and format, an exported file may not have the same protection as the encrypted vault. Read the official documentation for your specific manager before exporting, and avoid leaving export files in Downloads, cloud-sync folders, or email.
If you only need to move a modest number of business credentials, manual migration can be slower but easier to control. If you have hundreds of accounts, a documented export-and-import process may be reasonable. The decision should be based on scale and the product's guidance, not on the assumption that exporting is always the easiest option.
After any migration, test several critical logins from the new business context before deleting old copies. The point of separation is continuity, not speed. A clean-looking vault is not useful if the only working credential was removed during cleanup.
Fix ownership while you are already touching the account
Migration is a good moment to notice accounts that still belong to the wrong identity. When you open a business credential to move it, check the username or email address attached to the account. If the service supports changing it and a business address is more appropriate, consider making that change as part of the migration.
Do not combine too many risky changes at once. For a critical account, first confirm that you can sign in. Then update the ownership or recovery details according to the service's official process. Confirm the change. Only after that should you remove obsolete copies or old access. Keeping the sequence simple makes troubleshooting easier if something goes wrong.
If an account cannot be cleanly moved because it mixes personal purchases and business history, you may decide to leave the old account personal and create a new business account for future work. Separation does not always mean retroactively untangling every past decision. Sometimes the cleanest boundary starts today.
Use a short migration checklist, not a permanent cleanup project
A practical migration should end. Set a simple definition of done: your current business-critical accounts are in the business vault, the work browser profile reaches the correct accounts, obvious duplicates are resolved, and the old personal vault is no longer the default place for new business credentials.
You can review long-tail accounts later. The most important success is behavioral: from now on, business accounts are created and saved in the business context. Once the future flow is correct, the old backlog becomes smaller every time you encounter it.
Prioritize the logins that would interrupt current work if you lost access.
Sign in from the intended business context before removing anything old.
Update business email or recovery details only through the service's official account settings.
Keep one clear source of truth after you know the new business credential works.
Move old accounts when you next use them instead of turning the migration into an endless project.
Migrate by business importance, not alphabetically. Get current work into the right vault, test it, correct obvious ownership problems, and let older low-value accounts move gradually as you encounter them.
Maintain the boundary as your freelance business changes
Review the system when the business changes, not every week
A good password system should not demand constant maintenance. You do not need a weekly vault-cleaning ritual. Review the boundary when something meaningful changes: you replace a primary device, change business email, switch password managers, add a contractor, stop working with a long-term client, move to a new accounting platform, or discover that business credentials are appearing in the wrong personal context.
A lightweight quarterly or twice-yearly review can also be useful if your work changes quickly, but keep the review practical. Look for stale client access, duplicate business accounts, devices you no longer use, and credentials that are still tied to a personal identity for no good reason. You are checking whether the system still reflects reality, not trying to make the vault aesthetically perfect.
If nothing has changed and the separation remains clear, leave it alone. Security systems fail when they demand so much maintenance that people stop using them consistently.
Design today for one future collaborator, not a hypothetical corporation
Even if you work alone now, imagine that one trusted assistant, bookkeeper, collaborator, or subcontractor may need access to part of the business later. Would you have to hand over your personal password-manager login to make that possible? If the answer is yes, your current boundary may be too personal.
You do not need to buy an enterprise plan today. You do need to understand whether your chosen system can add business access later without exposing your personal vault. Look for a path that preserves individual accounts and business ownership rather than encouraging one shared master login.
That future test is useful because it reveals whether the business vault is truly a business asset or merely a folder inside your private digital life. The goal is not to predict your company size. It is to avoid a setup that can grow only by sharing something that should remain personal.
Keep the separation understandable to your future self
The person most likely to inherit this system may simply be you six months from now after a busy season. Use names and rules that do not require memory. If your business vault has unusual exceptions, record a short note explaining them. If one important account must remain tied to a personal email, note why. If a client requires a particular credential workflow, note that the access is client-owned.
A few clear rules are more durable than dozens of clever folders. The system should survive travel, a device replacement, a long vacation, and the ordinary stress of deadline week. If you can return after a month away and immediately know where a new business credential belongs, the design is working.
Personal stays personal. Business-created accounts start in the business context. Client-owned access stays clearly labeled. New credentials are saved correctly the first time.
If your setup needs more rules than you can remember, simplify the architecture before adding another folder, app, or vault.
A sustainable password manager for a freelance business should need occasional review, not constant administration. Make the ownership rules obvious enough that they still work when your tools, devices, or client list changes.
Frequently Asked Questions
Not always. A separate business account can create a strong ownership boundary, but one password manager can also work if it provides clearly separated personal and business vaults or spaces. The important test is whether you can reliably save and autofill business credentials without exposing or confusing them with personal credentials. If the separation is unclear, a separate business account may be simpler.
Start with credentials that exist because of your business: business email, domain and website administration, invoicing tools, cloud storage used for work, professional software, scheduling, project platforms, and other accounts that your freelance operation depends on. Keep client-owned credentials clearly labeled so they are not confused with accounts your business owns.
A separate browser profile is useful for organization, but it should not be treated as the only security boundary on a shared or untrusted device. Browser profiles can help keep work history, bookmarks, accounts, and saved information separate, while device access controls and your password manager protect the credentials themselves. Use the profile as a visible work context, not as a substitute for device security.
Decide which side should own the account long term. If separating the existing account is difficult, you can keep it where it currently belongs and create a new business account for future work when the service allows it. The goal is not to rewrite every past decision. The goal is to make new business activity consistently use the business identity.
No. Many solo freelancers can use one trusted laptop or phone while keeping business and personal accounts separated through user profiles, browser profiles, vaults, and clear account ownership. Separate devices can be useful in higher-risk or policy-controlled situations, but they are not automatically necessary for a practical freelance setup.
Use the smallest structure that answers real questions. A few broad groups such as Core Business, Marketing, Production, Finance Tools, and Client Access may be enough. Naming and ownership are usually more important than deep folder trees. If you rarely use a folder to find or review credentials, you probably do not need it.
Review it when your business changes: after replacing a device, changing business email, adding a collaborator, switching password managers, ending a major client relationship, or noticing credentials appearing in the wrong context. A periodic review can help, but the system should not require constant maintenance to remain usable.
A simple system you can keep using
Separating personal and business passwords is not about creating more passwords to remember. A well-designed system should do the opposite. It should reduce the number of decisions you make because the correct business identity, vault, and browser context are already obvious.
Start with ownership. Decide which accounts belong to your private life, which belong to your freelance business, and which belong to clients. Then choose the lightest password-manager structure that preserves those boundaries. For some freelancers, that will be separate vaults inside one manager. For others, a dedicated business password-manager account will create cleaner ownership and recovery.
After that, make the separation visible in daily work. Use a dedicated work browser context where practical, save new business credentials directly to the business vault, and keep autofill suggestions focused on the accounts you actually need. Do not wait for a future cleanup project to correct new mistakes.
Finally, let the system stay boring. Review it when devices, clients, tools, or collaborators change. If you can open your laptop, enter the work context, and reach the right accounts without thinking about where the passwords live, the boundary is doing its job.
Open your current password manager and identify only your five most important freelance accounts. Mark each one as personal, business-owned, or client-owned. Then move the business-owned credentials into one clearly labeled business location and use that location as the default for every new work account from today forward.
Sam Na writes BudgetFlow Studio guides for freelancers, creative professionals, and digital nomads who want practical systems for managing the operational side of independent work. His focus is on reducing unnecessary admin while making everyday business workflows easier to understand, maintain, and review.
This guide provides general information about organizing and separating personal and business credentials. The right setup can vary with your devices, password manager, client agreements, workplace rules, and the services you use. For decisions involving sensitive client access, regulated work, or important account-recovery changes, review the official documentation for the relevant service and, where appropriate, confirm the requirements with a qualified security professional or the organization that owns the account.
The following official resources were used to verify the security and account-separation principles discussed in this guide.
NIST — SP 800-63B-4: Digital Identity Guidelines, Authentication and Authenticator Management UK National Cyber Security Centre — Password Manager Buyers Guide Google Chrome Help — Manage Chrome with Multiple Profiles